Pillar 02 · Trust
Cybersecurity
Wisconsin has already adopted the one model law most states argue about. The remaining work is readiness and coordination, not another statute.
Where this stands
The insurance data-security model is already law here.
Wisconsin adopted the NAIC Insurance Data Security Model Law in 2021 Act 73, codified at Wis. Stat. §§ 601.95–601.956. Licensees maintain an information security program, investigate incidents, and notify the Commissioner. That is a real obligation and it is in statute, not in guidance.
We say this plainly because it changes what is worth asking for. Several states are still fighting over that model. Wisconsin is not, and a business league that came to the Capitol demanding a law the state passed five years ago would be telling legislators it had not read the code.
Our position
Readiness, procurement, and not mistaking paperwork for security.
Where we think there is useful work: coordinated incident response between the state, local government and the private operators who are actually attacked first; procurement standards that let small Wisconsin vendors meet a security bar without a compliance department; and resisting the reflex to answer every incident with a new attestation requirement, which raises cost without raising the floor.
This is a watching brief rather than a bill campaign. If a vehicle appears — and a serious incident at a Wisconsin institution would produce one within a session — the position above is what we would bring to it.
Bill numbers, votes and committee composition are drawn from the Wisconsin Legislature and Legislative Council records; lobbying registrations from Wisconsin Ethics Commission filings. See the legislative tracker for live bill status, or the full agenda for how this fits the two pillars.